Nokogiri NULL Pointer Dereference
High severity
GitHub Reviewed
Published
Jan 17, 2019
to the GitHub Advisory Database
•
Updated Dec 4, 2025
Description
Published by the National Vulnerability Database
Jul 19, 2018
Published to the GitHub Advisory Database
Jan 17, 2019
Reviewed
Jun 16, 2020
Last updated
Dec 4, 2025
A NULL pointer dereference vulnerability exists in the
xpath.c:xmlXPathCompOpEval()function of libxml2 through 2.9.8 when parsing an invalid XPath expression in theXPATH_OP_ANDorXPATH_OP_ORcase. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.References